live wire
AI · Red Hat documents usage-based admission fair sharing for Kueue 1.4 on OpenShiftRed Hat DeveloperAI: Red Hat maps governed firewall changes from ServiceNow through Ansible and two human approval gatesRed Hat DeveloperCLUSTER MGMT · ACM 2.17 makes Submariner 0.24 GA with Important-rated fixesRed Hat ErrataPLATFORM · Red Hat makes on-premises Lightspeed recommendations GA for Satellite 6.18Red Hat ErrataSECURITY · Red Hat Hardened Images updates Tomcat 10 for nine authentication, access-control and DoS flawsRed Hat ErrataAI · Open Data Hub 3.6.0 EA1 bundles Trainer, MLflow and llm-d componentsOpen Data HubAI · Speculators 0.6.0 adds P-EAGLE parallel drafting for vLLM speculative decodingRed Hat DeveloperSECURITY · OpenShift 4.17.57 fixes seven Go and TLS CVEs in an Important-rated updateRed Hat ErrataAI · Red Hat benchmarks local LLM guardrails with EvalHub, exposing regex accuracy and latency trade-offsRed Hat DeveloperAI · Red Hat maps silent tool-call failures across agentic pipelinesRed HatAPI · Kuadrant 1.5.3 adds GRPCRoute policies and developer-portal API-key workflowsKuadrantAI · (Aug 25) IBM releases Apache-2.0 Granite 4.2 reasoning models in 3B, 8B and 30B sizesIBM ResearchJAVA · Red Hat build of Quarkus 3.33.3.SP1 fixes 13 CVEs in an Important-rated updateRed Hat errataAI · vLLM moves Kimi K2 RL weight sync across 384 H100s in 7.53 seconds (Aug 22)vLLMAI · Red Hat documents usage-based admission fair sharing for Kueue 1.4 on OpenShiftRed Hat DeveloperAI: Red Hat maps governed firewall changes from ServiceNow through Ansible and two human approval gatesRed Hat DeveloperCLUSTER MGMT · ACM 2.17 makes Submariner 0.24 GA with Important-rated fixesRed Hat ErrataPLATFORM · Red Hat makes on-premises Lightspeed recommendations GA for Satellite 6.18Red Hat ErrataSECURITY · Red Hat Hardened Images updates Tomcat 10 for nine authentication, access-control and DoS flawsRed Hat ErrataAI · Open Data Hub 3.6.0 EA1 bundles Trainer, MLflow and llm-d componentsOpen Data HubAI · Speculators 0.6.0 adds P-EAGLE parallel drafting for vLLM speculative decodingRed Hat DeveloperSECURITY · OpenShift 4.17.57 fixes seven Go and TLS CVEs in an Important-rated updateRed Hat ErrataAI · Red Hat benchmarks local LLM guardrails with EvalHub, exposing regex accuracy and latency trade-offsRed Hat DeveloperAI · Red Hat maps silent tool-call failures across agentic pipelinesRed HatAPI · Kuadrant 1.5.3 adds GRPCRoute policies and developer-portal API-key workflowsKuadrantAI · (Aug 25) IBM releases Apache-2.0 Granite 4.2 reasoning models in 3B, 8B and 30B sizesIBM ResearchJAVA · Red Hat build of Quarkus 3.33.3.SP1 fixes 13 CVEs in an Important-rated updateRed Hat errataAI · vLLM moves Kimi K2 RL weight sync across 384 H100s in 7.53 seconds (Aug 22)vLLM
upstreambeat.ai
releaseSECURITY

OpenShift AI 3.4.4 security update reaches from the Operator to serving and workbench images

The Critical-rated release touches 106 image families and 143 CVEs; operators need the platform update, not only the earlier AI Inference image replacements.

OpenShift AI 3.4.4 security coverage across many components.
Chart: figures from the story
By The News Desk· Aug 28, 2026

Red Hat has issued a Critical-rated OpenShift AI 3.4.4 security update that reaches far beyond a single model-server image. RHSA-2026:60520 lists updated platform images, while Red Hat’s machine-readable CSAF advisory identifies 143 vulnerabilities and 106 distinct image families across the release.

What is in the update

The image list spans the OpenShift AI control plane and operator assets, including the Operator bundle, Operator controller, dashboard, CLI and must-gather image. It also reaches the platform’s model-serving layer: KServe controllers and router, llm-d scheduling and routing components, Models-as-a-Service controllers, Llama Stack, the model-serving API and vLLM CPU runtime all appear in the advisory.

The same update refreshes workbench and pipeline runtimes, notebook controllers, MLflow, Feast, KubeRay, Spark and distributed-training images. Trust and safety components are represented too, including TrustyAI services, guardrail detectors and the guardrails orchestrator. The practical point is that the 143-CVE count is spread across a broad platform bill of materials; it does not describe 143 flaws in one OpenShift AI service.

The Operator upgrade path

Red Hat’s remediation text tells customers to move their clusters to OpenShift AI 3.4.4, but it also says the linked product documentation “will be updated shortly” with release-specific instructions. That is an important limitation in the public guidance at publication time: the advisory provides the fixed image set, but not a bespoke 3.4.4 runbook.

The current OpenShift AI 3.4 update-channel documentation says the installed Operator’s Subscription selects the channel used to track and receive Operator updates. Administrators should therefore verify that the Subscription is following the intended supported 3.4 channel, complete whatever approval step their Operator policy requires, and confirm that the Operator and its managed components have reconciled to the 3.4.4 images. Image-level verification matters because the erratum covers both operator-managed services and workload-facing runtimes.

Why this is not the earlier Inference 3.4.4 refresh

Red Hat separately published Important-rated 3.4.4 advisories for Red Hat AI Inference images on August 20. The CPU advisory covers one CPU serving image and five CVEs; separate advisories map the CUDA and Spyre variants to their replacement images.

RHSA-2026:60520 is the OpenShift AI platform update. Replacing a standalone AI Inference image does not update the OpenShift AI Operator, dashboard, KServe and llm-d control components, pipelines, workbenches or TrustyAI images listed in the newer advisory. Clusters running OpenShift AI 3.4 need the platform’s 3.4.4 update path even if their model-serving image was already refreshed under the earlier Inference advisories.

Filed by The News Desk. Corrections: desk@upstreambeat.ai · Our standards →

comments · 0

    Comments are moderated before they appear. Your email is used once to confirm it is you — never shown, never sold. Corrections and questions get an answer from the desk when we have one.